Legal
Product privacy notice
Last updated: 12 July 2026
This notice covers the StructLine service: the dashboard, the backend, and the StructLine browser extension. For visiting the structline.ai website, see the website privacy notice.
Three audiences read this page. If your organization is a StructLine customer, sections 1, 4–12 describe how we process data for you. If your employer has deployed StructLine on your work browser, section 2 is written for you. If you are reviewing the browser extension, section 3 describes exactly what it collects.
1. Who does what: roles under the GDPR
StructLine is a workplace tool. An organization (our customer) deploys it to discover which AI tools its team uses and what kinds of data flow into them.
- For the monitoring data the service produces (findings, the AI register, reports), the customer is the controller. It decides to deploy StructLine, chooses the privacy mode, and owns the data. StructQ Ltd is the processor, acting on the customer’s documented instructions under our data processing agreement.
- For account data (the names, work emails and login credentials of the people who sign in, billing details, and support correspondence), StructQ Ltd is the controller.
The controller for this website and for our own account records is StructQ Ltd, trading as StructLine, registered in England and Wales (company number 16685082), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, ICO registration ZB978258. Contact: [email protected].
2. If StructLine is deployed at your workplace
Your employer (or the organization that manages your work browser) is the controller for the data StructLine produces about AI usage. It is responsible for telling you StructLine is in use and for having a lawful basis to use it. This section summarizes what the tool can and cannot see, because we build that transparency in.
What your organization can see, by privacy mode
| Mode | What leaves your device | What your organization sees |
|---|---|---|
| Zero-retention (the default) | Metadata only: which AI tool, whether the account looked personal or corporate, the kinds of sensitive data detected (e.g. “an IBAN”, “an API key”), counts, and timestamps. The text you typed is analyzed on your device and never transmitted or stored. | Categories and counts only, without the values or the text. |
| Redacted excerpts (explicit opt-in by your organization) | An excerpt in which detected sensitive values are masked on your device before anything is sent. | The redacted excerpt, with sensitive values masked. |
| Full content (a separate, second opt-in with an explicit warning) | The text of the flagged interaction. | The stored content of flagged interactions. |
Built-in transparency
- Right after enrollment, and at any time afterwards, the extension shows you exactly what your organization can see under its current settings.
- If your organization ever enables content storage, the extension shows you a clear warning.
- Each step up in collection is recorded as a consent event in the organization’s audit trail.
What StructLine does not do
- It does not read your screen or log your keystrokes generally; it analyzes interactions with AI tools it recognizes.
- It does not tell your employer your personal account names or passwords; account classification (personal vs. corporate) is inferred from workspace markers and login domains, and is marked unknown rather than guessed when unclear.
- On the Discover and Comply plans it does not block, alter or mask what you type: it observes and reports. If your organization subscribes to the Enforce plan and an administrator turns enforcement on, policies your organization authors can warn you, coach you toward an approved tool, block a submission, or mask detected sensitive values in a prompt before it is sent. Every enforcement decision is made on your device, and what is recorded is metadata (which policy, which action, when), never the text of your prompt. The extension’s popup shows you when enforcement is on and how many rules apply to you.
- It does not read the AI’s responses. Where your organization uses Enforce’s tokenization, swapping tokens back to their original values in the page you see happens entirely in your browser, with a key that never leaves your device; nothing from the response is stored or transmitted.
- It never sends your data to third-party AI providers.
To exercise your data protection rights over workplace monitoring data, contact your employer; they control it, and we assist them. If you believe your employer has not told you about StructLine, you can also write to us at [email protected].
3. What the browser extension collects
The StructLine extension has a single purpose: detecting the use of AI tools on a work browser and identifying what kinds of sensitive data flow into them, for the deploying organization’s AI governance and compliance program. It is installed by or for an organization; it is not a consumer product.
- Web activity, narrowly: the extension detects visits to and prompts submitted to recognized AI tools. It does not collect general browsing history.
- On-device analysis: a deterministic, checksum-gated detection engine runs locally in the browser to classify sensitive data (financial identifiers, national IDs, credentials and secrets, crypto wallets).
- What is transmitted: in the default zero-retention mode, only metadata: tool, inferred account type, detected data categories, counts, timestamps, and an enrollment identifier linking the device to the organization. Content is transmitted only if the organization has explicitly opted into redacted-excerpt or full-content collection (section 2).
- Enforcement (Enforce plan only): if the deploying organization has enabled enforcement, the extension applies the organization’s policies on-device and transmits each decision as metadata only: the policy, the action taken (warn / coach / block / mask), the outcome, detected categories, counts, latency, tool host and time. The decision format has no field that can carry prompt or response content, and the tokenization key, where used, is generated on the device and never transmitted.
- Limited use: extension data is used only to provide the service to the deploying organization. We do not sell it, use it for advertising, or train AI models on it.
4. Data we process on our customers’ behalf
As processor, we process the following on behalf of each customer, org-scoped and tenant-isolated:
- Usage findings: AI tool, inferred account type (corporate / personal / unknown), detected sensitive-data categories and named schemes (“Visa”, “German Steuer-ID”), counts and scale estimates, risk level, timestamps, and the pipeline’s per-stage results.
- Optional content, only per the customer’s chosen privacy mode: redacted excerpts or, with a second explicit opt-in, full flagged content.
- Workforce directory data the customer provides: names, work emails, team membership, enrolled devices.
- Enforcement configuration and decisions (Enforce plan): the enforcement policies the customer authors (trigger, scope, action, message to the member) and a tamper-evident, hash-chained log of enforcement decisions: which policy matched, the action and outcome, detected categories, counts, latency, tool host and time. Metadata only, never the content acted on.
- Compliance artifacts generated from the above: the AI register, exposure reports, vendor due-diligence records, DPIA recommendations, and the audit trail (which records privileged actions as metadata only, never content or secret values).
5. Data we process as controller
| Data | Purpose | Lawful basis |
|---|---|---|
| Account data: name, work email, authentication identifiers (managed through our authentication provider, Clerk) | Sign-in, access control, session management | Art. 6(1)(b): performing the contract |
| Organization and billing details: billing contact name and email, billing address and, where provided, VAT number | Subscription management, payment processing and VAT calculation (via Stripe; payment card data is collected and held by Stripe, not by us), invoicing and accounting, tax records | Art. 6(1)(b), (c) |
| Support and service correspondence | Resolving issues, service announcements (handled in our corporate email, Microsoft 365) | Art. 6(1)(b), (f) |
| Service notification emails (e.g. finding alerts) | Alerting the administrators the customer designates | Art. 6(1)(b) |
Cookies in the product
The dashboard sets only strictly necessary cookies: the sign-in and session cookies of our authentication provider (Clerk) and, where needed, a short-lived security cookie from our network provider (Cloudflare). It sets no analytics or advertising cookies, which is why there is no cookie banner in the product. The browser extension sets no cookies; it keeps its configuration (enrollment, organization settings) in the browser’s extension storage, where it is needed to provide the service.
6. AI detection: self-hosted, no third-party AI
If a customer enables the optional AI detection stage, collected content is analyzed by an open-weights model running on infrastructure we control. No third-party AI provider is involved at any stage. We do not send data any external AI service, and we do not train models on customer data. In zero-retention mode no content is collected, so this stage does not run at all.
7. Retention, deletion and export
- Customer-controlled retention: each organization configures how long findings are kept.
- Tightening the privacy mode deletes data: when an organization switches to a stricter mode, we permanently delete any stored data the new mode does not allow. For example, moving from full-content collection back to zero-retention erases the stored content, because zero-retention keeps only metadata.
- Erasure: administrators can erase their organization’s data in one action; on termination we delete or return personal data per the DPA.
- The enforcement log is anonymized, not rewritten: to preserve its tamper-evident integrity, erasing a person removes their attribution from enforcement decision entries rather than deleting the entries; the remaining metadata no longer relates to an identifiable person. Retention trims the log from the oldest end.
- Export: per-person GDPR data export is built in, so customers can answer access requests from their workforce.
- Account data is kept for the life of the account and as required for legal and tax records afterwards.
8. Security
Data is encrypted in transit; each organization’s data is strictly tenant-isolated and org-scoped; access is role-based (administrator, read-only compliance viewer, and self-scoped users who see only their own activity); privileged actions are recorded in an audit trail as metadata only. Device enrollment uses single-use tokens. The technical and organizational measures are set out in Annex 2 of the DPA.
9. Sub-processors
The sub-processors we engage are published at structline.ai/trust/sub-processors together with our change-notification commitment. The list contains no external AI service and no analytics provider: the dashboard, the backend and the browser extension contain no third-party analytics or tracking. The consent-based analytics on our marketing website are separate, never run inside the product, and are covered by the website privacy notice.
10. Where your data is, and international transfers
The StructLine service runs on infrastructure we control in the European Union: the backend, database and dashboard are hosted on servers in Germany (Hetzner), operated for us by Inoqube d.o.o. (Slovenia). Your organization’s findings and any stored content are stored and processed at rest within the EU.
Traffic between enrolled browsers, dashboard users and the service transits Cloudflare’s global network, which we use for DNS, TLS and DDoS protection. That transit is encrypted, Cloudflare processes it only as a proxy, and the transfer is covered by the EU–US Data Privacy Framework and Standard Contractual Clauses (see the sub-processor list).
One category of personal data is held outside the EU: account and sign-in data (names, work emails, authentication identifiers) is processed by our authentication provider, Clerk, in the United States under Standard Contractual Clauses and the UK Addendum. Workforce monitoring data is never stored with Clerk.
Where a sub-processor processes personal data outside the UK or EEA, we rely on adequacy decisions or Standard Contractual Clauses with the UK International Data Transfer Addendum, as set out in the DPA and the sub-processor list. For UK customers, EU-to-UK access rests on the UK’s adequacy decision for the EEA.
11. Your rights
For account data (where we are controller): you have the UK/EU GDPR rights of access, rectification, erasure, restriction, portability and objection; write to [email protected]. You can complain to the ICO (ico.org.uk) or your local EEA supervisory authority.
For workplace monitoring data (where your employer is controller): direct requests to your employer; we provide them the tooling (per-person export, deletion) and assistance to respond. If a request reaches us directly, we will pass it to the relevant organization and tell you we have done so.
12. Changes and contact
We will update this notice as the service evolves, describing new capabilities here before they can affect personal data, as this notice now describes the Enforce plan’s on-device enforcement. Material changes are announced to customer administrators in advance.
Questions: [email protected], or StructQ Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.